📦 Cdg

by Esafenet

🔍 What is Cdg?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-42885

CRITICAL CVSS 9.1 Sep 5, 2024

This SQL injection vulnerability in ESAFENET CDG allows attackers to execute arbitrary SQL commands via the id parameter in data.jsp. Organizations using ESAFENET CDG version 5.6 and earlier are affec...

CVE-2025-3401

HIGH CVSS 7.3 Apr 8, 2025

A critical SQL injection vulnerability in ESAFENET CDG allows remote attackers to execute arbitrary SQL commands via the noticeId parameter in /parameter/getLimitIPList.jsp. This affects ESAFENET CDG ...

CVE-2025-3399

HIGH CVSS 7.3 Apr 8, 2025

A critical SQL injection vulnerability exists in ESAFENET CDG version 5.6.3.154.205_20250114, specifically in the /pubinfo/updateNotice.jsp file via the ID parameter. This allows remote attackers to e...

CVE-2025-1840

HIGH CVSS 7.3 Mar 3, 2025

This critical SQL injection vulnerability in ESAFENET CDG allows remote attackers to execute arbitrary SQL commands by manipulating the flowId parameter in the updateorg.jsp file. Organizations using ...

CVE-2025-0793

MEDIUM CVSS 6.3 Jan 29, 2025

This vulnerability allows remote attackers to execute SQL injection attacks on ESAFENET CDG V5 systems via the flowId parameter in the /todoDetail.jsp file. Organizations using ESAFENET CDG V5 are aff...

CVE-2025-0791

MEDIUM CVSS 6.3 Jan 29, 2025

CVE-2025-0791 is a critical SQL injection vulnerability in ESAFENET CDG V5's /sdDoneDetail.jsp endpoint via the flowId parameter. This allows remote attackers to execute arbitrary SQL commands on the ...

CVE-2025-0788

MEDIUM CVSS 6.3 Jan 28, 2025

This critical SQL injection vulnerability in ESAFENET CDG V5 allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in the /content_top.jsp file. This could lead to data thef...

CVE-2025-0786

MEDIUM CVSS 6.3 Jan 28, 2025

This critical SQL injection vulnerability in ESAFENET CDG V5 allows remote attackers to execute arbitrary SQL commands via the flowId parameter in the /appDetail.jsp file. All systems running the affe...

CVE-2024-10660

MEDIUM CVSS 6.3 Nov 1, 2024

This critical SQL injection vulnerability in ESAFENET CDG 5 allows remote attackers to execute arbitrary SQL commands via the deleteHook function. Organizations using ESAFENET CDG 5 are affected, pote...

CVE-2024-10613

MEDIUM CVSS 6.3 Nov 1, 2024

This critical SQL injection vulnerability in ESAFENET CDG 5 allows remote attackers to execute arbitrary SQL commands by manipulating the 'id' parameter in the delSystemEncryptPolicy function. Organiz...

CVE-2024-10611

MEDIUM CVSS 6.3 Nov 1, 2024

This critical SQL injection vulnerability in ESAFENET CDG 5 allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in the delProtocol function. Organizations using ESAFENET C...

CVE-2024-10596

MEDIUM CVSS 6.3 Oct 31, 2024

This critical SQL injection vulnerability in ESAFENET CDG 5 allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in the delEntryptPolicySort function. Attackers could poten...

CVE-2024-10594

MEDIUM CVSS 6.3 Oct 31, 2024

This critical SQL injection vulnerability in ESAFENET CDG 5 allows remote attackers to execute arbitrary SQL commands by manipulating the fileId parameter in the docHistory function. Attackers can pot...

CVE-2024-10501

MEDIUM CVSS 6.3 Oct 30, 2024

This critical SQL injection vulnerability in ESAFENET CDG 5 allows remote attackers to execute arbitrary SQL commands by manipulating the 'id' parameter in the findById function. This can lead to unau...

CVE-2024-10379

MEDIUM CVSS 4.3 Oct 25, 2024

This CVE describes a path traversal vulnerability in ESAFENET CDG 5 that allows attackers to read arbitrary files on the server by manipulating the decryptFileId parameter. The vulnerability affects s...

CVE-2024-10377

MEDIUM CVSS 6.3 Oct 25, 2024

This critical SQL injection vulnerability in ESAFENET CDG 5 allows remote attackers to execute arbitrary SQL commands by manipulating the 'id' parameter in the actionPassDecryptApplication1 function. ...

CVE-2024-10278

MEDIUM CVSS 6.3 Oct 23, 2024

This critical SQL injection vulnerability in ESAFENET CDG 5 allows remote attackers to execute arbitrary SQL commands by manipulating the userId parameter. This could lead to unauthorized data access,...

CVE-2024-10135

MEDIUM CVSS 6.3 Oct 19, 2024

This critical SQL injection vulnerability in ESAFENET CDG 5 allows remote attackers to execute arbitrary SQL commands by manipulating the 'id' parameter in the actionDelNetSecConfig function. Attacker...

CVE-2024-10134

MEDIUM CVSS 6.3 Oct 19, 2024

This critical SQL injection vulnerability in ESAFENET CDG 5 allows remote attackers to execute arbitrary SQL commands via the 'servername' parameter in the connectLogout function. Organizations using ...

CVE-2024-10072

MEDIUM CVSS 6.3 Oct 17, 2024

This critical SQL injection vulnerability in ESAFENET CDG 5 allows remote attackers to execute arbitrary SQL commands by manipulating the 'checklist' parameter in the actionAddEncryptPolicyGroup funct...

CVE-2024-10069

MEDIUM CVSS 6.3 Oct 17, 2024

This critical SQL injection vulnerability in ESAFENET CDG 5 allows remote attackers to execute arbitrary SQL commands by manipulating the 'id' parameter in the MailDecryptApplicationService. Organizat...